Trust
How we think about your customers' privacy
Sylo answers the most trusted line in your business. Your customers call it to say when they'll be home, what needs fixing, and where they live. Here's the thing we never let ourselves forget: those people didn't choose us. They chose you. We hold their information on your behalf, and that framing drives every privacy decision we make. This post is the plain-language version of how we operate; the precise version lives on our security page and in our privacy policy.
Callers should never be misled
Sylo doesn't pretend to be a human. If a caller asks whether they're talking to an AI, it tells the truth. We think trust in your business is the asset at stake on every call, and a receptionist that lies about what it is spends that asset on your behalf.
Recording works the same way. Sylo applies the recording disclosure that matches your caller's jurisdiction, including the stricter rules in two-party consent states and a consent script for international callers, and it keeps an audit log of every disclosure it plays.
Your data is fenced, structurally
Every row of data in Sylo carries your business's identifier, and the database itself enforces that boundary on every read and write, not just the application code above it. Before any AI model sees a piece of your data, it's re-verified as yours a second time in the retrieval layer.
Just as important: there is no cross-tenant learning. Your knowledge base, your call history, and your customers never train another business's receptionist. What your business teaches Sylo stays inside your fence.
Conversations are not telemetry
To run a reliable service we monitor errors, latencies, and call metadata. What we don't put in our logs is the conversation itself. The content of your customers' calls and messages lives in your dashboard, where it belongs, and a redaction filter strips known-sensitive fields before any log leaves our systems. When we debug a problem, we're looking at what happened, not at what was said.
Deletion means deletion
You can export everything Sylo holds for your business as a single file, any time, from your dashboard. You can also delete your account entirely, self-serve, with no support ticket and no retention games.
The same right extends to your customers as individuals. If someone asks your business to be forgotten, you can erase them in one confirmed step: transcripts, learned details, and message copies included. And if you cancel, your data stays available to you for 30 days and is then purged automatically. That purge isn't a policy sentence; it's a scheduled process.
About our vendors
Running Sylo takes a small, vetted set of third-party processors for things like infrastructure, telephony, AI runtime, and email. Each one is bound by a data processing agreement, and international transfers are governed by standard contractual clauses. We don't publish the list by name, because our vendor stack is also our security surface; where your contract requires disclosure, we provide it under NDA. The full terms are in our data processing addendum.
What we haven't earned yet
We don't have a SOC 2 report today; a Type I is targeted before public launch, with Type II after. We don't claim HIPAA compliance, and we don't claim ISO 27001. You'll find the same admissions on our security page, because we'd rather tell you where we are than dress up where we aren't.
Privacy promises are easy to write and hard to keep. Ours are kept in the same codebase that answers your phone, which is the only place a promise like this counts. If you have a question we haven't answered, write to info@wayhow.ai and we'll give you a straight answer, including "not yet" when that's the honest one.